Information Security GRC Lead
Summary
Leads information security governance, risk and compliance (GRC) at Good Energy, coordinating assurance over IT security controls, PCI-DSS, penetration testing, disaster recovery and change governance while Technology Teams own technical implementation. Hybrid role based in Chippenham, Wiltshire with one office day per week.
Reporting into the Head of IGRC, this role provides information security GRC oversight, coordination and assurance across IT security, resilience and control governance, working closely with Technology Teams who retain ownership of technical implementation and day-to-day system administration.
We are seeking a practical and technically capable Information Security GRC Lead to help strengthen Good Energy’s security and control environment. This role will act as a key link between IGRC and Technology Teams; identifying security and compliance requirements, coordinating activity, providing guidance and challenge, evidencing controls, and tracking remediation. The role is not expected to perform day-to-day technical administration but will need sufficient technical understanding to work effectively with the Technology Teams who implement and operate the controls.
- IT Security Governance: Maintain oversight of IT security risks, controls, policies and standards, helping define what good control looks like and working with Technology Teams to ensure ownership, implementation and evidence are clear.
- Security Control Assurance: Coordinate and evidence regular assurance over information technology security controls across people, process, premises and technology, working with Technology Teams to validate control operation, escalate gaps and track remediation.
- Information Security Risk and Compliance: Support information security risk and compliance activity by interpreting relevant standards and good practice frameworks, translating requirements into practical actions, and working with Technology Teams to support proportionate implementation.
- Security Incident Support: Support security incident response by helping assess governance, risk and compliance impacts, coordinating evidence, supporting root cause analysis and ensuring lessons learned are tracked with the relevant technical owners
- IT Disaster Recovery and Resilience: Coordinate oversight and challenge of IT disaster recovery arrangements, working with Technology Teams to maintain plans, schedule testing, evidence outcomes, identify dependencies and track remediation of weaknesses.
- IT Change Management: Support effective IT change governance, including chairing or supporting the Good Energy Change Advisory Board, and ensuring security and resilience impacts are considered and that technical owners complete agreed actions before implementation where required.
- PCI-DSS Compliance: Coordinate and support PCI-DSS control activity, evidence gathering, control testing and remediation tracking where technology controls are in scope.
- Penetration Testing and Vulnerability Management: Coordinate penetration testing and support vulnerability management oversight, working with Technology Teams and third parties to risk assess findings, agree ownership and monitor remediation without taking ownership of technical remediation activity.
- Technology Policy and Awareness: Develop, review and maintain technology security policies, standards and guidance, supporting employee awareness of key security responsibilities.
As the Information Security GRC Lead, you will be a proactive, practical and technically aware individual who can work confidently between IGRC, Technology Teams and wider business teams.
You will be comfortable working independently, influencing across teams and maintaining focus on practical risk reduction, strong evidence and continuous improvement.
- Good understanding of information technology security, information security risk and control management.
- Experience supporting, coordinating or assuring IT security controls, vulnerability management, incident response, IT disaster recovery or IT change governance, ideally while working alongside technical teams who own implementation.
- Awareness of recognised security standards or frameworks such as ISO27001, Cyber Essentials, NCSC CAF and PCI-DSS.
- Strong verbal and written communication skills, with the ability to explain technical matters clearly to non-technical audiences.
- Demonstrable attention to detail and ability to produce clear, evidence-based documentation.
- Ability to interpret technical workflows, risks and controls and translate them into practical procedures, policies, or assurance activity and clear actions for technical owners.
- Confident working with stakeholders across technology, governance and business teams to agree actions and track remediation.
- Experience working in a regulated sector, ideally energy, with exposure to Smart Metering security obligations, governance or assurance requirements.
- Experience coordinating CREST-accredited penetration testing, reviewing findings, agreeing remediation plans and tracking closure with technical owners.
- Relevant qualification or certification such as ISO27001 Foundation or Implementer, CISMP, SSCP, Security+, CISA or equivalent experience.
- Working knowledge of data protection requirements where they intersect with technology security controls.
Hybrid working explained: When and where you’ll be in the office
Our office is based in Chippenham, Wiltshire. For this role, we're looking for candidates who can come in to our Chippenham office, once a week.
We offer both formal and informal flexible working options. Full-time hours are 37.5 per week, Monday to Friday.
The office is fully accessible, allowing everyone to participate fully in their working lives regardless of any mobility challenges. We promote work-life balance and flexibility through hybrid working, which combines both remote and office work.
🏡 £500 work from home allowance - an annual allowance paid monthly alongside your salary to support with working from home costs.
🚆 £500 travel allowance - an annual allowance paid monthly alongside your salary to support with travelling to work costs.
🎁 15% annual bonus: company-wide bonus scheme designed to reward collective teamwork and delivery of results across the whole business.